CVE-2026-45796: Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint

Published May 19, 2026
·
Updated

Summary

Unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint (POST /api/v2/workspaceagents/azure-instance-identity). An external attacker can force the Coder server to issue HTTP GET requests to arbitrary internal or external hosts by submitting a crafted PKCS#7 signature. The server does not return the target's response body, but error messages in the API response reveal whether the target is reachable and what type of failure occurred.

Details

The POST /api/v2/workspaceagents/azure-instance-identity endpoint accepts a PKCS#7 signature without authentication. During certificate chain verification, azureidentity.Validate() iterates over the signer certificate's IssuingCertificateURL extension and fetches each URL using http.DefaultClient with no host restriction, no private-IP blocking, and no response-size limit.

An attacker crafts a self-signed certificate whose Common Name matches .metadata.azure.com (passing the allowedSigners regex) and whose IssuingCertificateURL points to an attacker-chosen target. The server fetches that URL and feeds the response body into x509.ParseCertificate. The parsed result is discarded, but the wrapped error string is returned verbatim in the JSON response via Detail: err.Error(). Connection-level errors ("connection refused", "i/o timeout", DNS failures) and certificate-parse errors give the attacker enough signal to infer host reachability and port state without seeing the actual response content.

Root causes:

1. No allowlist on IssuingCertificateURL hosts. Any URL was accepted. 2. http.DefaultClient was used. It follows redirects and connects to private, link-local, and loopback addresses. 3. Unbounded io.ReadAll on the response body (memory exhaustion vector). 4. Raw err.Error() was returned in the JSON response, leaking internal HTTP client errors to the caller.

Impact

This is a semi-blind SSRF: the server makes the outbound request but the HTTP response body is consumed by x509.ParseCertificate and never returned to the attacker.

- Internal network reconnaissance. The attacker can map internal hosts and ports by observing error differentiation in the API response: "connection refused" (port closed), "i/o timeout" (host unreachable or firewalled), DNS failure (host does not exist), or certificate-parse error (port open and responding). This enables systematic scanning of the internal network from the Coder server's vantage point. - Requests to sensitive endpoints. The server can be directed to hit cloud metadata services (e.g. http://169.254.169.254/), internal admin interfaces, or other services. The attacker cannot read the response content, but the request itself may have side effects depending on the target. - Error-based information disclosure. Wrapped Go HTTP client errors in the Detail field expose internal hostnames, IP addresses, port numbers, and network topology details. - Memory exhaustion. The unbounded io.ReadAll on the response body allows an attacker to point IssuingCertificateURL at a large resource, forcing the server to buffer it entirely in memory.

Patches

Fixed in #25274 (commit 57b11d405):

The fix was backported to all supported release lines:

| Release line | Patched version | |---|---| | 2.33 | v2.33.3 | | 2.32 | v2.32.2 | | 2.31 | v2.31.12 | | 2.30 | v2.30.8 | | 2.29 | v2.29.13 | | 2.24 (ESR) | v2.24.5 |

Workarounds

If the Azure identity-auth mechanism is not being used then restrict access to the corresponding endpoint (/api/v2/workspaceagents/azure-instance-identity) using ingress firewall and/or proxy ACLs.

Recognition

We'd like to thank Ben Tran of calif.io and Anthropic's Security Team (ANT-2026-22447) for independently disclosing this issue!

Other sources

Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint (POST /api/v2/workspaceagents/azure-instance-identity). An external attacker can force the Coder server to issue HTTP GET requests to arbitrary internal or external hosts by submitting a crafted PKCS#7 signature. The server does not return the target's response body, but error messages in the API response reveal whether the target is reachable and what type of failure occurred. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, if the Azure identity-auth mechanism is not being used then restrict access to the corresponding endpoint (/api/v2/workspaceagents/azure-instance-identity) using ingress firewall and/or proxy ACLs.

MITRE

Affected Software

13 affected componentsFixes available
go/github.com/coder/coder<=0.27.3
go/github.com/coder/coder/v2<2.24.5
2.24.5
go/github.com/coder/coder/v2>=2.29.0<2.29.13
2.29.13
go/github.com/coder/coder/v2>=2.30.0<2.30.8
2.30.8
go/github.com/coder/coder/v2>=2.31.0<2.31.12
2.31.12
go/github.com/coder/coder/v2>=2.32.0-rc.0<2.32.2
2.32.2
go/github.com/coder/coder/v2>=2.33.0-rc.0<2.33.3
2.33.3
Coder Coder Go<2.24.5
Coder Coder Go>=2.29.0<2.29.13
Coder Coder Go>=2.30.0<2.30.8
Coder Coder Go>=2.31.0<2.31.12
Coder Coder Go>=2.32.0<2.32.2
Coder Coder Go>=2.33.0<2.33.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.24.5
  2. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.29.13
  3. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.30.8
  4. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.31.12
  5. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.32.2
  6. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.33.3
  7. Upgrade

    Upgrade coder to a version that resolves this vulnerability.

    Fixed in 2.24.5
  8. Upgrade

    Upgrade coder to a version that resolves this vulnerability.

    Fixed in 2.29.13
  9. Upgrade

    Upgrade coder to a version that resolves this vulnerability.

    Fixed in 2.30.8
  10. Upgrade

    Upgrade coder to a version that resolves this vulnerability.

    Fixed in 2.31.12
  11. Upgrade

    Upgrade coder to a version that resolves this vulnerability.

    Fixed in 2.32.2
  12. Upgrade

    Upgrade coder to a version that resolves this vulnerability.

    Fixed in 2.33.3
  13. Compensating control

    If the Azure identity-auth mechanism is not being used, restrict access to the endpoint /api/v2/workspaceagents/azure-instance-identity using ingress firewall and/or proxy ACLs.

Event History

May 19, 2026
Advisory Published
via GitHub·07:53 PM
Data Sourced
via GitHub·07:53 PM
DescriptionSeverityWeaknessAffected Software
Jul 7, 2026
CVE Published
via MITRE·09:03 PM
Data Sourced
via MITRE·09:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-45796?

CVE-2026-45796 has a medium severity rating of 6.5.

2

How does CVE-2026-45796 affect applications?

CVE-2026-45796 allows attackers to exploit unauthenticated semi-blind Server-Side Request Forgery (SSRF) by making requests through an exposed endpoint.

3

Who is impacted by CVE-2026-45796?

Any application utilizing the affected versions of the Coder software may be vulnerable to CVE-2026-45796.

4

How can I fix CVE-2026-45796?

To mitigate CVE-2026-45796, upgrade to the latest version of Coder that addresses this vulnerability.

5

What is the nature of the attack vector for CVE-2026-45796?

The attack vector for CVE-2026-45796 involves sending crafted POST requests to the Azure instance identity endpoint.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203